<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Problem with Forcing Asymmetric Traffic Through Specific Gateway]]></title><description><![CDATA[<p dir="auto">Hello everyone,</p>
<p dir="auto">I need your help because I'm lost. I need to pass asymmetric requests, but I'm failing every time.</p>
<p dir="auto">Let me explain: server 10.30.0.20 sends requests on port 445 to server 10.15.55.10. The request arrives through the gateway between the EdgeRouter and Netgate 1, and then goes to server 10.15.55.10. This works, I can see the requests arriving.</p>
<p dir="auto">The problem is that I have a static route 10.30.0.0/24 that goes to another gateway in another Netgate, and I cannot delete this static route. Therefore, the response requests do not leave the TEST interface where server 10.15.55.10 is located.</p>
<p dir="auto">In summary, I have a rule on the Netgate interface that connects it to the EdgeRouter that I have set to "sloppy", and another rule on the TEST interface with source 10.15.55.10:445 to 10.30.0.20 with the gateway between the Netgate and the EdgeRouter to force the request to go through this path, but nothing works.</p>
<p dir="auto">I hope I have been clear enough and that someone can help me. Thank you.!<br />
<img src="/assets/uploads/files/1744631912105-diagramme-sans-nom.drawio.png" alt="Diagramme sans nom.drawio.png" class=" img-fluid img-markdown" /></p>
]]></description><link>https://forum.netgate.com/topic/197137/problem-with-forcing-asymmetric-traffic-through-specific-gateway</link><generator>RSS for Node</generator><lastBuildDate>Tue, 14 Jul 2026 13:42:15 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/197137.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 14 Apr 2025 11:58:47 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Problem with Forcing Asymmetric Traffic Through Specific Gateway on Thu, 17 Apr 2025 11:17:57 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/viragomann">@<bdi>viragomann</bdi></a><br />
Hello,</p>
<p dir="auto">Thank you for your help. I changed the default routing to create an additional static route for this unique IP, in order to replace the subnet route. And for accesses that require it, I create policy-based rules.</p>
<p dir="auto">Have a very good day.</p>
]]></description><link>https://forum.netgate.com/post/1212523</link><guid isPermaLink="true">https://forum.netgate.com/post/1212523</guid><dc:creator><![CDATA[philippe richard]]></dc:creator><pubDate>Thu, 17 Apr 2025 11:17:57 GMT</pubDate></item><item><title><![CDATA[Reply to Problem with Forcing Asymmetric Traffic Through Specific Gateway on Mon, 14 Apr 2025 14:33:16 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/philippe-richard">@<bdi>philippe-richard</bdi></a><br />
I'd favor the masquerading solution, but the natting must be done on the edge router. How to do this, depends on the device. Presumably it's not Netgate?</p>
<p dir="auto">On pfSense you can do this with an outbound NAT rule.</p>
]]></description><link>https://forum.netgate.com/post/1212240</link><guid isPermaLink="true">https://forum.netgate.com/post/1212240</guid><dc:creator><![CDATA[viragomann]]></dc:creator><pubDate>Mon, 14 Apr 2025 14:33:16 GMT</pubDate></item><item><title><![CDATA[Reply to Problem with Forcing Asymmetric Traffic Through Specific Gateway on Mon, 14 Apr 2025 13:53:05 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/viragomann">@<bdi>viragomann</bdi></a><br />
It's complicated because it's a migration, and some things cannot be changed at the moment.<br />
As English is not my native language, I sometimes have difficulty understanding.<br />
What do you mean by creating a 'sloppy' rule on the TEST interface, or doing a NAT?</p>
]]></description><link>https://forum.netgate.com/post/1212238</link><guid isPermaLink="true">https://forum.netgate.com/post/1212238</guid><dc:creator><![CDATA[philippe richard]]></dc:creator><pubDate>Mon, 14 Apr 2025 13:53:05 GMT</pubDate></item><item><title><![CDATA[Reply to Problem with Forcing Asymmetric Traffic Through Specific Gateway on Mon, 14 Apr 2025 13:08:27 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/philippe-richard">@<bdi>philippe-richard</bdi></a><br />
So as I got you, on Netgate 1 you have a static route for 10.30.0.0/24 pointint to Netgate 2, but 10.30.0.20 is behind the edge router? WTF! Why?</p>
<p dir="auto">Then you have a routing issue, which cannot be solved with sloppy state rules at all. Yeah, as its best, with a sloppy state policy routing rule on the TEST interface, directing traffic to the edge router.</p>
<p dir="auto">But I'd rather masquerade the traffic from 10.30.0.20 on the edge router, which seems more reliable to me.</p>
]]></description><link>https://forum.netgate.com/post/1212233</link><guid isPermaLink="true">https://forum.netgate.com/post/1212233</guid><dc:creator><![CDATA[viragomann]]></dc:creator><pubDate>Mon, 14 Apr 2025 13:08:27 GMT</pubDate></item><item><title><![CDATA[Reply to Problem with Forcing Asymmetric Traffic Through Specific Gateway on Mon, 14 Apr 2025 12:41:39 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/viragomann">@<bdi>viragomann</bdi></a> said in <a href="/post/1212227">Problem with Forcing Asymmetric Traffic Through Specific Gateway</a>:</p>
<blockquote>
<p dir="auto">10.30.0.20</p>
</blockquote>
<p dir="auto">Hello Viragomman, I hope you are doing well. To answer your question, I cannot create a static route to that single address because other computers need to connect to 10.30.0.20 through this default route. That's why I'm trying to create a policy-based rule, but I'm not succeeding.</p>
]]></description><link>https://forum.netgate.com/post/1212229</link><guid isPermaLink="true">https://forum.netgate.com/post/1212229</guid><dc:creator><![CDATA[philippe richard]]></dc:creator><pubDate>Mon, 14 Apr 2025 12:41:39 GMT</pubDate></item><item><title><![CDATA[Reply to Problem with Forcing Asymmetric Traffic Through Specific Gateway on Mon, 14 Apr 2025 12:18:13 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/philippe-richard">@<bdi>philippe-richard</bdi></a> said in <a href="/post/1212225">Problem with Forcing Asymmetric Traffic Through Specific Gateway</a>:</p>
<blockquote>
<p dir="auto">The problem is that I have a static route 10.30.0.0/24 that goes to another gateway in another Netgate, and I cannot delete this static route. Therefore, the response requests do not leave the TEST interface where server 10.15.55.10 is located.</p>
</blockquote>
<p dir="auto">If you don't need to static route for 10.30.0.20, what I don't assume, I'd just rather create an additional static route for this single IP to override the subnet route then messing with sloppy states rules.</p>
]]></description><link>https://forum.netgate.com/post/1212227</link><guid isPermaLink="true">https://forum.netgate.com/post/1212227</guid><dc:creator><![CDATA[viragomann]]></dc:creator><pubDate>Mon, 14 Apr 2025 12:18:13 GMT</pubDate></item></channel></rss>